首页 | 本学科首页   官方微博 | 高级检索  
     

基于攻击规划图的实时报警关联方法
引用本文:张靖,李小鹏,王衡军,李俊全,郁滨.基于攻击规划图的实时报警关联方法[J].计算机应用,2016,36(6):1538-1543.
作者姓名:张靖  李小鹏  王衡军  李俊全  郁滨
作者单位:信息工程大学 密码工程学院, 郑州 450001
基金项目:信息保障技术重点实验室开放基金资助项目(20151014)。
摘    要:针对报警因果关联分析方法存在无法及时处理大规模报警且攻击场景图分裂的不足,提出一种基于攻击规划图(APG)的实时报警关联方法。该方法首先给出APG和攻击规划树(APT)的定义;其次,根据先验知识构建APG模型,并提出基于APG的实时报警关联方法,重建攻击场景;最后,结合报警推断完善攻击场景和预测攻击。实验结果表明,该方法能够有效地处理大规模报警和重建攻击场景,具有较好的实时性,可应用于分析入侵攻击意图和指导入侵响应。

关 键 词:报警关联  因果关系  攻击规划图  攻击场景  报警推断  实时性  
收稿时间:2015-11-23
修稿时间:2016-02-26

Real-time alert correlation approach based on attack planning graph
ZHANG Jing,LI Xiaopeng,WANG Hengjun,LI Junquan,YU Bin.Real-time alert correlation approach based on attack planning graph[J].journal of Computer Applications,2016,36(6):1538-1543.
Authors:ZHANG Jing  LI Xiaopeng  WANG Hengjun  LI Junquan  YU Bin
Affiliation:College of Cryptography Engineering, Information Engineering University, Zhengzhou Henan 450001, China
Abstract:The alert correlation approach based causal relationship has the problems that it cannot be able to process massive alerts in time and the attack scenario graphs split. In order to solve the problem, a novel real-time alert correlation approach based on Attack Planning Graph (APG) was proposed. Firstly, the definition of APG and Attack Planning Tree (APT) were presented. The real-time alert correlation algorithm based on APG was proposed by creating APG model on basis of priori knowledge to reconstruct attack scenario. And then, the attack scenario was completed and the attack was predicted by applying alert inference mechanism. The experimental results show that, the proposed approach is effective in processing massive alerts and rebuilding attack scenarios with better performance in terms of real-time. The proposed approach can be applied to analyze intrusion attack intention and guide intrusion responses.
Keywords:alert correlation  casual relationship  Attack Planning Graph (APG)  attack scenario  alert inference  real-time  
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号